Trust
Security at Semantiks
Effective date: August 5, 2026 · Last updated: August 5, 2026
This page describes the security controls that apply to the Semantiks platform today. It is written for security reviewers, and it states current reality rather than intent. Where a control is in progress, this page says so and gives a date.
Certifications. Semantiks does not hold a SOC 2 report or an ISO 27001 certificate today. An ISO 27001:2022 programme has been active since July 20, 2026, and the audit engagement is projected to begin on September 20, 2026. We publish no certification date until an accredited certification body has confirmed its own. Our real-time control posture is public in our Trust Center.
1. Compliance programme and independent assurance
- ISO 27001:2022 programme — active since July 20, 2026, with continuous control monitoring through Vanta. Audit engagement projected to begin September 20, 2026. An engagement letter is available on request.
- Trust Center — continuously updated control posture, policies, and frameworks, public at app.vanta.com/semantiks.ai/trust.
- External penetration test — an independent test by Workstreet is scheduled for September 2026. An attestation letter will be available to customers and prospects under NDA on completion. Semantiks has not previously commissioned an external penetration test.
- Security incidents — Semantiks has experienced no security incidents affecting Customer Data to date.
2. Where Customer Data is stored and processed
Customer Data is stored and processed in the United States. Semantiks runs on Google Cloud Platform and Amazon Web Services:
- Application compute and media storage — Google Cloud Platform, us-central1 and us-east4.
- Primary application database — Amazon Web Services, us-east-2.
- Analytics processing — United States.
Personnel access. Semantiks personnel who access production systems are engaged directly by Semantiks Inc. under United States contracts and are bound by the confidentiality and access controls described below. No Customer Data is stored outside the United States.
3. Encryption
- In transit — TLS 1.2 or higher for all connections to the Services.
- At rest — AES-256 across databases, object storage, and backups.
4. Artificial-intelligence model providers
OpenAI is the sole model provider used in production. No other model provider receives Customer Data. Semantiks operates under an OpenAI Enterprise Agreement, executed July 1, 2026, which contractually prohibits the use of Customer Data to train generalized models. Semantiks likewise does not use Customer Data to train generalized models.
Customer conversations, including transcriptions of end-user voice messages, are processed by OpenAI to generate agent responses. Media that end users send in a conversation — images, documents, and voice messages — is stored in Semantiks-controlled storage in the United States.
5. Access to production systems
- Access to production systems containing Customer Data is restricted to a limited subset of Semantiks personnel, granted by role and reviewed as roles change.
- Same-day revocation of all access on departure.
- Confidentiality agreements are signed by all personnel and contractors.
- Multi-factor authentication is enforced on our core internal systems. Coverage across all remaining internal systems completes in August 2026.
6. Secure development
- Mandatory peer code review on all changes.
- Branch protection on production branches.
- Automated dependency vulnerability scanning.
7. Human oversight of agent decisions
Semantiks agents operate under human supervision rather than in isolation. Customers have:
- Real-time conversation supervision — live visibility into agent conversations as they happen.
- Human takeover — any conversation can be escalated to and taken over by a human agent through the contact centre.
- Configurable human review — the degree of automation in agent outcomes is configurable per customer, including requiring human evaluation before a final disposition.
8. Subprocessors
Semantiks maintains a current register of subprocessors that may process Customer Data, identifying each provider, its purpose, and its hosting location. The register is provided to customers and prospective customers under a non-disclosure agreement on request, rather than published, and forms part of the Data Processing Addendum.
9. Retention and deletion
Customers may request export or deletion of Customer Data, including during the term and on termination. Deletion requests are executed by the Semantiks engineering team; automated, customer-initiated deletion is in development. Retention periods, the post-termination export window, and residual backup copies are described in the Privacy Notice, and contractual deletion timelines are set in the Data Processing Addendum.
10. Security incidents
Semantiks notifies affected customers of a confirmed security incident affecting their Customer Data without undue delay, and provides the information reasonably available to support the customer’s own legal obligations. Specific notification windows are committed contractually in the Data Processing Addendum. Semantiks has experienced no security incidents to date.
11. Availability
Semantiks does not publish an uptime figure at this time, and will not quote one until it is backed by measurement. A public status page is in progress. Availability commitments, where offered, are set in the applicable customer agreement.
12. Reporting a security issue
Report suspected vulnerabilities or security concerns to [email protected]. We acknowledge reports and will work with you on validation and remediation. We do not pursue legal action against researchers who report in good faith, avoid privacy violations and service degradation, and give us reasonable time to remediate before disclosure.
13. Related documents
- Terms of Service
- Privacy Notice
- Trust Center
- Data Processing Addendum — provided on request
- Subprocessor register — provided under NDA on request